Privacy Policy
Version 3.3 · effective August 31, 2026 · still in force
TheGuys App LLC
Effective Date: August 31, 2026
1. Introduction
This Privacy Policy describes how TheGuys App LLC, a Wyoming limited liability company with principal place of business at 1883 West Royal Hunte Drive, Suite 200A, Cedar City, Utah 84720 ("TheGuys App," "we," "us," or "our"), collects, uses, and shares personal information when you use TheGuys.app and related mobile and web applications (the "Platform"). This Privacy Policy applies to all individuals and entities that register for, access, or use the Platform, including any User who uses the embedded accounting and bookkeeping feature described in Section 22 (the "Accounting Feature"). It also applies to Clients — the customers of a Dispatcher who receive an invoice through the Platform, open the invoice payment page, or pay an invoice through the Platform — as described in Section 23, even though a Client, as such, does not hold an Account.
This Privacy Policy is incorporated by reference into the Terms of Service and forms part of your agreement with us. Capitalized terms used but not defined here have the meanings given in the Terms of Service.
By using the Platform, including the invoice payment page, you acknowledge that you have read and understood this Privacy Policy.
1.1 A Note on Vocabulary
This Privacy Policy uses the formal terms "Dispatcher" (a User who posts a Job and engages other Users), "Performer" (a User who accepts and performs a Job), and "Client" (a third party who receives services from a Dispatcher and is invoiced by that Dispatcher for those services; a Client, in that capacity, does not have an Account). Within the Platform's user-facing interface a Dispatcher may informally be called a "Boss," a Performer may informally be called a "Guy," and a Client may informally be called a "customer." Those informal terms are gender-neutral. The formal terms control in this Privacy Policy.
2. Who We Are and How to Contact Us
The data controller for personal information collected through the Platform is:
TheGuys App LLC 1883 West Royal Hunte Drive, Suite 200A Cedar City, Utah 84720
Email for privacy questions and rights requests: legal@theguys.app
To exercise any of the privacy rights described in Section 13, please email legal@theguys.app with the subject line "Privacy Rights Request." See Section 14 for the full request process.
3. Scope of This Privacy Policy
3.1 What This Policy Covers
This Privacy Policy covers personal information we collect when you:
- Visit TheGuys.app (the marketing site)
- Register for an Account on the Platform
- Use the Platform in any role (whether as a Dispatcher with respect to a Job, a Performer with respect to a Job, or both)
- Use the Accounting Feature for your own bookkeeping
- Communicate with us
- Receive or respond to text messages, emails, or other communications related to your use of the Platform
- Receive an invoice from a Dispatcher through the Platform, open the invoice payment page, or pay an invoice through the Platform, as a Client (see Section 23)
3.2 What This Policy Does NOT Cover
- Information practices of third-party services we integrate with (Stripe, Twilio, Resend, Anthropic, Supabase, Vercel, Upstash, Sentry, Google services, and Plaid Inc. or another bank-data aggregator if you choose to link a bank account through the Accounting Feature). Each of these has its own privacy policy. Section 9 lists these third parties.
- Information practices of websites or services linked from the Platform but not operated by us.
- Information you share with other Users directly off the Platform.
- Information about a person who is neither a User nor a Client but whose contact details have been entered into the Platform by a Dispatcher (for example, a person a Dispatcher has invited to join but who has not registered). Where a Dispatcher enters a Client's details on an invoice and sends that invoice through the Platform, the information we collect from and about that Client is covered by Section 23.
4. Information We Collect
We collect personal information in three ways: (a) directly from you, (b) automatically as you use the Platform, and (c) from limited third-party sources. This Section 4 describes what we collect from Users. If you are a Client, the information we collect from and about you is described in Section 23.
4.1 Information You Provide Directly
When you register an Account or use the Platform, we collect:
Identity and contact information
- Your legal name, business name (if any), email address, mobile phone number, mailing address or service area, and government-issued identification if we request identity verification.
Account credentials and security
- Your password (stored in hashed and salted form), two-factor authentication settings if enabled.
Payment-related information
- Stripe Connected Account identifiers and limited transaction history, and (if you activate the Accounting Feature subscription) subscription status and invoice metadata. Full payment-card details are stored by Stripe, not by us.
Job-related information
- Job descriptions, task checklists, schedules, locations, rates, Job acceptances, completion data, expense entries, receipts, photos, and notes you submit when posting or performing a Job.
Client invoice information (Dispatchers)
- The Client invoices you create: the Client's name, business name, email address, phone number, and billing address as you enter them; the line items, prices, and notes you bill; the invoice number, dates, and status; the copy of each invoice as sent; and, where the Client pays through the Platform, the payment record described in Section 23.
Private notes and ratings
- Notes you maintain about other Users you have engaged; ratings, reviews, or feedback you submit about other Users.
Financial and bookkeeping data (Accounting Feature)
- Business identification: company name, address, fiscal-year start, accounting method, and branding (color, logo).
- Manual journal entries: account assignments, dates, descriptions, amounts, debit and credit allocations.
- Categorization and tags: chart-of-accounts assignments, automation rules, vendor or payee names.
- Receipts: image and PDF uploads attached to transactions.
- CSV imports: bookkeeping data you choose to import from another system.
- Period close passwords: stored in hashed form only and used to authenticate the reopening of closed accounting periods.
- Bank transaction data (only if you connect a bank account): description, amount, date, status, and account balance, transmitted from Plaid Inc. or another bank-data aggregator at your authorization.
- Generated reports: profit-and-loss, balance sheet, general ledger, trial balance, and reconciliation outputs created from your data.
The Accounting Feature deliberately does NOT collect, store, or process: Social Security Numbers, Taxpayer Identification Numbers (TIN/EIN), credit card numbers (these stay with Stripe), bank account numbers or routing numbers (these stay with the bank-data aggregator), payroll data, sales tax filings, or any data required for 1099 or W-2 issuance. See the Accounting Feature description in Section 22.
Communications with us
- Support requests, complaints, and any other communications you send to us.
4.2 Information We Collect Automatically
Device and connection data
- IP address, device type, operating system, browser type, browser language, mobile carrier (for SMS routing), time zone and approximate location derived from IP.
Usage data
- Pages or screens visited, features used, links clicked, time spent, login and logout events, Job activity, Accounting Feature actions, and error/diagnostic data.
Location data (precise GPS)
- When you check in to or out of a Job using the Platform's GPS check-in feature, we collect your precise GPS coordinates and a timestamp. This data is collected in real time at the moment you check in or check out, not continuously.
- We do NOT track your location continuously, in the background, when you are not actively using the Platform's check-in feature, or while you are using the Accounting Feature.
Photographs, receipts, and media
- Photos you upload as part of Job submissions (completion photos, receipt photos).
- Receipt images and PDFs you upload as part of bookkeeping in the Accounting Feature.
- Photo metadata (such as EXIF data, which may include date, time, device, and sometimes GPS coordinates embedded by your camera).
Reliability metrics
- Internal metrics about your activity on the Platform (acceptance rate, response time, check-in timing, task completion, photo quality, expense accuracy). These metrics inform AI engagement recommendations and are not used by, generated from, or shared with the Accounting Feature.
Audit logs (Accounting Feature)
- Every change to journal entries, accounts, configuration, or user permissions in the Accounting Feature is automatically logged with: identity of the actor, timestamp, before and after values, and the source event ID where applicable. Audit logs are designed to meet GAAP audit-trail standards and IRS recordkeeping requirements and are retained for the period described in Section 11.
Cookies and similar technologies
- See Section 10 for details on cookies and tracking.
4.3 Information from Third Parties
We may receive limited information about you from:
- Stripe — confirmation that your Connected Account onboarding was completed; Stripe-issued account identifiers; payout status and dispute notifications; payment-event metadata that flows into the Accounting Feature's event ledger. We do not receive or store your full bank account number or full payment card number from Stripe.
- Plaid Inc. or another bank-data aggregator — ONLY if you choose to link a bank account or credit card to the Accounting Feature for automated transaction import. The aggregator transmits bank transaction descriptions, amounts, dates, status, and balances into your books. The aggregator holds your bank login credentials directly; we do not see or store them.
- Identity verification services (if used) — confirmation of identity verification results.
- Other Users — information that another User submits about you.
We do not purchase personal information from data brokers or marketing-list providers.
5. Sensitive Personal Information
Several state privacy laws define a category of "sensitive personal information" that requires heightened protections. Under those laws, we may collect the following categories of sensitive personal information:
- Precise geolocation — collected only at the moment of GPS check-in or check-out for a Job, as described in Section 4.2. Not collected by the Accounting Feature.
- Account credentials — your password (stored in hashed form only).
- Government-issued identifiers — only if we request identity verification.
- Financial account information — ONLY if you link a bank account through the Accounting Feature, in which case bank transaction data (description, amount, date, status, balance) is transmitted from your chosen bank-data aggregator into your books. We do not collect or store your bank login credentials, full bank account numbers, or routing numbers.
We do NOT collect: race, ethnicity, religion, philosophical beliefs, union membership, genetic or biometric data, health data or medical records, sex-life information, citizenship or immigration status, Social Security Numbers, or Taxpayer Identification Numbers.
We use sensitive personal information only for the limited purposes described in Section 6. We do not use sensitive personal information for advertising, marketing, profiling unrelated to the service, or any purpose that you would not reasonably expect.
6. How We Use Personal Information
6.1 Provide the Platform
- Create and maintain your Account; authenticate you and protect your Account.
- Process Job postings, acceptances, completions, and payments.
- Generate Client invoices on behalf of Users acting as Dispatchers (without disclosing what the Dispatcher paid the Performer), email those invoices to Clients at the Dispatcher's direction, operate the invoice payment page, process Client payments through Stripe, and deliver paid receipts (see Section 23).
- Deliver text messages and email notifications you have consented to receive.
6.2 Operate the Accounting Feature
- Record, store, organize, and display the bookkeeping data you enter.
- Generate profit-and-loss, balance sheet, general ledger, trial balance, and reconciliation outputs from your data.
- Maintain audit logs of every change to your books.
- Receive and record bank transaction data (only if you have authorized a bank-data aggregator).
- Provide read-only access to accountants or bookkeepers you specifically invite.
- Administer your Accounting Feature subscription and billing.
- We do NOT use Accounting Feature data to: generate AI engagement recommendations on the Platform, train AI models in identifiable form, market to you, or share it in identifiable form with any third party except as described in Section 9. De-identified, aggregated data derived from Accounting Feature data is governed by Sections 9.7 and 22.8.
6.3 Operate the AI Tools
- Use Job-related content as inputs to the AI Tools described in Section 10 of the Terms of Service. AI Tools do not access, train on, or generate output from Accounting Feature data.
6.4 Improve the Platform
- Analyze usage patterns; develop new Platform features; train and improve our internal AI models using only de-identified, aggregated data drawn from non-Accounting-Feature surfaces (see Section 8).
6.5 Communicate with You
- Respond to support requests and privacy rights requests; send Account notifications, security alerts, and Platform-operational messages.
6.6 Enforce Our Agreements and Protect Rights
- Detect, investigate, and prevent fraud, abuse, prohibited conduct, or violations of the Terms of Service or Acceptable Use Policy.
- Enforce our agreements; assert, defend, or settle legal claims; protect the security and integrity of the Platform and our Users.
6.7 Comply with Law
- Comply with applicable laws, regulations, court orders, subpoenas, and other legal process — including tax and recordkeeping laws that mandate retention of Accounting Feature financial records.
6.8 Create De-Identified and Aggregated Data
- Create de-identified, aggregated data sets and statistical insights — such as regional cost, demand, rate, and operational trend data — from Platform data, as described in Section 9.7. This data does not identify you, your business, or any individual.
7. Legal Bases for Processing
- Performance of a contract. We process your information as needed to operate the Platform under our contract with you.
- Consent. Where we rely on your consent (such as SMS or bank-account linking), you may withdraw consent at any time.
- Legitimate interests. We process information for our legitimate interests in operating, securing, and improving the Platform.
- Legal obligation. We process and retain information as required to comply with applicable law, including tax retention requirements applicable to Accounting Feature records.
8. AI and Automated Processing
8.1 What AI Tools Do
The Platform uses AI Tools to draft Job postings and task checklists, generate engagement recommendations, review photographs submitted by Performers, generate Client invoices, and answer Job-related and Platform-related questions in-product.
8.2 AI Tools Are Recommendations Only
All decisions on the Platform with legal or economic effect are made by Users, not by AI Tools.
8.3 Data Used by AI Tools
AI Tools may process Job content, photographs, expense data, GPS check-ins, reliability metrics, and dispatcher private notes. AI Tool processing is done by our service provider Anthropic under a commercial agreement that prohibits Anthropic from using Platform inputs to train Anthropic's general AI models.
8.4 AI Tools Do Not Touch Accounting Feature Data
We do not use Accounting Feature data — including journal entries, vendor or payee names, financial reports, audit logs, period-close passwords, receipt uploads, or bank-feed data — as input to any AI Tool, and we do not use this data to train any AI model in identifiable form. Aggregated, anonymized usage statistics about the Accounting Feature (for example, how many Users use a given feature) may be used for product analytics.
8.5 Your Right to Opt Out of Profiling
Where applicable state law grants you the right to opt out of profiling that produces legal or similarly significant effects, you may exercise that right under Section 13.
9. How We Share Personal Information
9.1 With Other Users on the Platform
- A Dispatcher sees Performer-related information for Jobs the Dispatcher has posted.
- A Performer sees Dispatcher-related information for Jobs the Performer has accepted.
- Multi-Tier Hierarchy — same visibility rules at each tier.
- Clients — receive the Dispatcher's invoice, the invoice payment page for that invoice, and — where the Client pays through the Platform — a paid receipt. A Client sees the Dispatcher's business name and contact details on the invoice; a Client never sees what the Dispatcher paid any Performer. In turn, the Dispatcher sees the status of each invoice the Dispatcher sent (emailed, first viewed, paid, and the amount and date paid); Performers never see Client payment details.
- Accounting Feature data is NOT shared with other Users on the Platform. Your books are visible only to you and to specific persons you have invited (typically your accountant or bookkeeper) under Section 23.10 of the Terms of Service.
9.2 With Service Providers
We share limited personal information with third-party service providers that help us operate the Platform. These service providers process information on our behalf and are contractually restricted from using it for any other purpose.
| Service Provider | Purpose | What They Receive |
|---|---|---|
| Stripe, Inc. | Payment processing (Stripe Connect Express), including Client payments of invoices | Payment, payout, and identity-verification data; for a Client who pays through the Platform, the payment-card details the Client enters into Stripe's payment form (which never pass through our servers), the Client's email address for the payment record, and the payment amount and outcome |
| Twilio, Inc. | SMS dispatch and messaging | Mobile phone numbers, message content, delivery status |
| Resend | Transactional email, including invoice and receipt emails to Clients | Email addresses, message content, delivery status |
| Anthropic, PBC | AI Tools (Claude API) — Job/Platform surfaces only | Job content, photos, expense data; subject to Anthropic's commercial-use restrictions. NOT Accounting Feature data. |
| Supabase, Inc. | Database and authentication infrastructure | All Platform data stored in our database, including Accounting Feature data and Client invoice and payment records |
| Vercel, Inc. | Hosting and web-application delivery | Platform requests and responses; access logs |
| Upstash, Inc. | Rate limiting and abuse prevention (short-lived request counters) | IP addresses and request counts, held only for the duration of the rate-limit window (minutes to about one hour) |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | Error reports and diagnostic data about failed requests (stack traces, request paths, browser and device type); we do not intentionally send payment-card data, passwords, or message content |
| Plaid Inc. (or comparable bank-data aggregator) | Bank-feed integration for Accounting Feature — ONLY if you authorize a bank connection | Bank credentials (provided by you directly to Plaid, not to us); bank transaction data transmitted to us |
| Google LLC (Maps Platform, reCAPTCHA) | Address auto-complete, mapping, anti-bot protection | Addresses; signup events; reCAPTCHA tokens |
We may add or change service providers from time to time; the current list is always available on request to legal@theguys.app.
9.3 For Legal and Safety Reasons
We may disclose personal information when we have a good-faith belief that doing so is necessary to comply with legal process, enforce our agreements, detect fraud or abuse, or protect the rights, property, or safety of TheGuys App, our Users, or any other person.
9.4 In Connection with a Business Transaction
If TheGuys App is involved in a merger, acquisition, financing, reorganization, or sale of all or substantially all of its assets, personal information may be transferred as part of that transaction.
9.5 With Your Consent or at Your Direction
We share personal information with other parties when you specifically consent or direct us to (for example, when you invite an accountant or bookkeeper to access your Accounting Feature books).
9.6 No Sale, No Sharing for Cross-Context Behavioral Advertising
We do not sell your personal information to anyone.
We do not "share" your personal information for cross-context behavioral advertising.
We do not engage in advertising of any kind on the Platform.
We do not share Accounting Feature data in identifiable form with any third party except as described in Section 9.2 (service providers strictly necessary to operate the feature) and Section 9.5 (persons you specifically invite). De-identified, aggregated data is addressed in Section 9.7.
No mobile information, including phone numbers and SMS opt-in or consent data, will be shared with or sold to third parties or affiliates for marketing or promotional purposes.
9.7 De-Identified and Aggregated Data
We create de-identified, aggregated data from Platform data — including Job, transaction, usage, and Accounting Feature data — and may use, license, or sell that data to third parties, for example as regional cost indexes, demand and materials trend feeds, or operational benchmark statistics. De-identified, aggregated data is not personal information: it does not identify you, your business, or any individual, and cannot reasonably be linked to any of them.
We publicly commit that we (a) take reasonable technical and organizational measures to ensure this data cannot be associated with any person or business, (b) maintain and use it only in de-identified form and do not attempt to re-identify it, except solely to test the effectiveness of our de-identification safeguards, and (c) contractually prohibit every recipient from attempting re-identification and require them to maintain the data in de-identified form. Statistics are published only at aggregation levels designed to prevent any contributor from being identified or singled out.
Because de-identified, aggregated data is not personal information, it is not subject to the access, correction, deletion, or portability rights in Section 13, and it may be retained and used after your Account closes. The commitments in Section 9.6 regarding personal information are unaffected: we do not sell your personal information, and no identifiable data leaves the Platform except as this Policy describes.
10. Cookies and Similar Technologies
We use cookies and similar technologies (such as local storage, session storage, and pixels) to operate the Platform. Categories: strictly necessary, functional, analytics, and security. We do not use cookies for advertising, retargeting, or cross-context behavioral tracking. You can control cookies through your browser settings; disabling strictly-necessary cookies will impair or prevent your use of the Platform.
11. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy or as required by law. Note that financial records in the Accounting Feature are subject to a mandatory retention period under tax law and cannot be deleted on request during that period; see Sections 13.3 and 22.4.
| Data category | Retention period |
|---|---|
| Account data (name, email, phone, login history) | For the life of your Account, plus seven (7) years after Account closure |
| Payment and transaction data (Platform-level), including Client invoice payment records and paid receipts | Seven (7) years after the transaction |
| Client invoices (the invoice content, the Client's name and contact details as entered by the Dispatcher, and each copy as sent) | Seven (7) years after the invoice was issued or paid, whichever is later |
| Invoice payment page activity (hashed IP address, hashed browser identifier, open/pay events and outcome codes) | Retained with the related invoice and payment records, then deleted or de-identified |
| Rate-limit counters (IP address and request count) | Automatically expire at the end of the rate-limit window (minutes to about one hour) |
| Job records (postings, completions, photos, expenses, GPS check-ins) | Seven (7) years after Job completion |
| SMS consent audit trail | Seven (7) years after Account closure |
| Reliability metrics | Active for the life of your Account; archived for seven (7) years |
| Private notes | For the life of the authoring User's Account, plus archive for seven (7) years |
| Accounting Feature: journal entries, transaction ledger, reconciliations, audit logs, receipts | Mandatory retention under tax law (commonly seven (7) years in the U.S., longer in some jurisdictions). Not deletable on request during this period — see Sections 13.3 and 22.4 |
| Accounting Feature: account-level configuration (branding, preferences, chart of accounts setup) | For the life of your Account, plus thirty (30) days for export, then deletable on request |
| Support communications | Three (3) years from resolution of the matter |
| Server logs | Up to twelve (12) months |
| Backups | Up to thirty-five (35) days after deletion of the underlying record |
| Prospective-invitee contact information (non-User) | Up to ninety (90) days, unless refreshed |
When data is no longer needed and no legal retention obligation applies, we delete it or de-identify it. De-identified data may be retained indefinitely for the purposes described in Section 8.4.
12. Data Security
We use reasonable administrative, technical, and physical safeguards to protect personal information. These include:
- Encryption in transit — all communications use TLS 1.2 or higher.
- Encryption at rest — AES-256 encryption for stored data.
- Row-level security — database-enforced account isolation. For the Accounting Feature, every table includes an owner identifier and a row-level security policy that prevents cross-account access even in the event of a malformed query or SQL injection attempt.
- Authentication and access control — passwords stored in hashed and salted form; access to production systems is limited and protected by strong authentication.
- Audit logging — security-relevant events and Accounting Feature changes are logged for review.
- Immutability controls — Accounting Feature financial records are locked from edit after period close, with all reopening events permanently audit-logged.
- Vendor diligence — service providers are reviewed before engagement.
No system is perfectly secure. While we use reasonable measures, we cannot guarantee that personal information will never be improperly accessed or disclosed. Suspected security incidents may be reported to admin@theguys.app.
12.1 Breach Notification
If a security incident affects your personal information and applicable law requires notification, we will notify you and applicable regulators within the time required by law.
13. Your Privacy Rights
We grant the following rights to all U.S. residents who use the Platform — including Clients who receive an invoice or use the invoice payment page — regardless of state of residence, subject to the legal-obligation carve-outs described below.
13.1 Right to Know / Access
You have the right to request confirmation of whether we are processing your personal information, the categories of information collected, the sources, the business purposes, the categories of third parties with whom we share, and the specific pieces of personal information we hold about you.
13.2 Right to Correct
You have the right to request that we correct inaccurate personal information about you.
13.3 Right to Delete
You have the right to request that we delete your personal information, subject to the following exceptions:
- Legal retention obligations. Information we are legally required to retain — including without limitation financial records in the Accounting Feature subject to tax-law retention (commonly seven (7) years in the U.S.) — cannot be deleted on request during the required retention period. After the retention period expires, you may renew your deletion request.
- Fraud, abuse, and security records. Records we retain to detect, investigate, prevent, or respond to fraud, abuse, security incidents, or unauthorized access cannot be deleted on request.
- Other legal exceptions. Standard exceptions under applicable state privacy laws (such as records relating to a transaction we are completing for you, exercising free speech rights, or other circumstances explicitly excepted from deletion under those laws).
Account-level Accounting Feature data that is not part of the legally-retained financial record (such as branding configuration or user preferences) is deletable on request.
13.4 Right to Data Portability
You have the right to receive a copy of your personal information in a structured, commonly used, and machine-readable format. For Accounting Feature data, the CPA Package export (Section 23.8 of the Terms of Service) satisfies this right.
13.5 Right to Opt Out of Sale or Sharing
We do not sell or share personal information for cross-context behavioral advertising. There is therefore no opt-out mechanism for sale or sharing — but you have the right to be informed of this fact.
13.6 Right to Limit Use of Sensitive Personal Information
We use sensitive personal information only as described in Section 5. Our use is already limited.
13.7 Right to Opt Out of Profiling
To the extent we engage in profiling that produces legal or similarly significant effects, you have the right to opt out.
13.8 Right to Non-Discrimination
We will not discriminate against you for exercising any of these rights.
13.9 Right to Appeal
If we decline a rights request, you have the right to appeal that decision.
14. How to Exercise Your Privacy Rights
14.1 How to Submit a Request
Send an email to legal@theguys.app with subject line "Privacy Rights Request" and your full name, the email address associated with your Account (or, if you are a Client, the email address the invoice was sent to and the invoice number), a description of the right you are exercising, and any information needed for us to verify your identity.
14.2 Identity Verification
To protect against fraudulent rights requests, we will verify your identity before fulfilling a request.
14.3 Authorized Agents
You may designate an authorized agent to make requests on your behalf.
14.4 Timing of Response
We will acknowledge your request within ten (10) business days and respond substantively within forty-five (45) days. We may extend this period by an additional forty-five (45) days when reasonably necessary.
14.5 No Fees
We do not charge a fee to respond to privacy rights requests, except where requests are excessive, repetitive, or manifestly unfounded.
15. State-Specific Disclosures
The following supplemental disclosures apply to residents of specific states. State-specific rights are subject to the same legal-obligation carve-outs in Section 13.3, including the tax-law retention rule for Accounting Feature records.
15.1 California Residents (CCPA / CPRA)
In the twelve months preceding the effective date of this Privacy Policy, we have collected the following categories of personal information about California consumers: identifiers; customer-records information; internet/network activity; geolocation; commercial information; professional/employment-related information; financial information (for Users of the Accounting Feature); inferences drawn from any of the foregoing; and sensitive personal information. We have not sold or shared (as those terms are defined under the CCPA/CPRA) any personal information about California consumers in that period.
15.2 Florida Residents (Florida Digital Bill of Rights)
Florida residents have the rights described in Section 13. We extend the rights to all Florida residents regardless of whether the FDBR's thresholds technically apply to us.
15.3 Wyoming Residents
Wyoming residents have the rights described in Section 13. As of the effective date of this Privacy Policy, Wyoming has not enacted a comprehensive consumer privacy law; nevertheless, we extend the same rights set to Wyoming residents that we extend to residents of states with comprehensive privacy laws.
15.4 Utah Residents
Utah residents have the rights described in Section 13.
15.5 Other State Residents
Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Delaware, New Jersey, New Hampshire, Nebraska, Minnesota, Maryland, Rhode Island, Kentucky, and any other state with a comprehensive privacy law have the rights described in Section 13.
16. Children's Privacy
The Platform is not intended for, and we do not knowingly collect personal information from, anyone under the age of 18. If we become aware that we have collected personal information from a person under 18, we will delete it as promptly as reasonably possible.
17. International Users
The Platform is intended for use by residents of the United States. We host data in the United States. We do not solicit or knowingly accept registrations from individuals located outside the United States.
18. Third-Party Links and Services
The Platform may contain links to third-party websites or integrate with third-party services. Those websites and services have their own privacy policies, which we do not control. Relevant providers and their privacy policy links include: Stripe (https://stripe.com/privacy), Twilio (https://www.twilio.com/legal/privacy), Resend (https://resend.com/legal/privacy-policy), Anthropic (https://www.anthropic.com/privacy), Supabase (https://supabase.com/privacy), Vercel (https://vercel.com/legal/privacy-policy), Plaid (https://plaid.com/legal), and Google (https://policies.google.com/privacy).
19. Privacy Practices for Other Users' Personal Information
When you act as a Dispatcher and submit information about another person — including a Client whose name, email address, and billing address you enter on a Client invoice — you act as a separate controller with respect to that information. You represent that you have a lawful basis to collect that person's information and that you have provided required notices. You agree to honor any rights requests from that person. Where you send a Client invoice through the Platform, we process the Client's information as described in Section 23 to deliver the invoice and, if the Client chooses, to collect payment on it; the invoice, the amounts billed, and any refund, credit, or dispute remain yours.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The current version is always available at https://theguys.app/privacy (which opens https://theguys.app/legal/privacy-policy). When we make material changes, we will update the "Last Updated" date, provide notice by email and/or in-Platform notification, and where required by law, obtain your consent.
21. Contact Us
For questions, concerns, or rights requests under this Privacy Policy, contact us at:
TheGuys App LLC 1883 West Royal Hunte Drive, Suite 200A Cedar City, Utah 84720
Email: legal@theguys.app
22. Accounting Feature — Privacy-Specific Disclosures
22.1 What the Accounting Feature Is
The Accounting Feature (also commercially known as "TheGuyBooks") is an embedded bookkeeping module within the Platform that allows Users to record financial transactions, generate financial reports, attach receipts, and export bookkeeping data. The Accounting Feature is operated entirely within TheGuys.app's own database infrastructure by TheGuys App LLC. All bookkeeping data — including journal entries, chart-of-accounts data, transaction records, imported transaction data, reconciliation records, and any names, descriptions, or notes you enter — is hosted, stored, and processed on infrastructure located in the United States, using the infrastructure providers identified in Section 9.2. The Accounting Feature does not move money; all money movement is processed by Stripe under Section 6 of the Terms of Service.
22.2 Data Categories Specific to the Accounting Feature
In addition to the data categories described in Section 4, the Accounting Feature collects:
- Business identification (company name, address, fiscal-year start, accounting method, branding)
- Manual journal entries you create
- Categorization, tags, and automation rules
- Vendor or payee names you enter
- Receipt and document uploads (image and PDF)
- CSV imports of bookkeeping data
- Period-close passwords (stored in hashed form only)
- Bank transaction data transmitted from Plaid Inc. or another bank-data aggregator, only if you connect a bank account
- Audit logs of every change made within the Accounting Feature
- Subscription status and billing metadata for the Accounting Feature subscription (payment-card details remain with Stripe)
The Accounting Feature does NOT collect Social Security Numbers, Taxpayer Identification Numbers, credit card numbers, bank login credentials, or full bank account or routing numbers.
22.3 Bank-Feed Authorization (If You Use It)
Bank-feed import via Plaid Inc. (or a comparable bank-data aggregator) is optional. If you choose to use it, the aggregator receives your bank credentials directly from you at your authorization. We do not see or store your bank login credentials. The aggregator transmits transaction data into your books. Your authorization is subject to the aggregator's own terms and privacy policy. You may revoke the authorization at any time.
22.4 Retention and Deletion of Financial Records
Financial records in the Accounting Feature — including journal entries, the transaction ledger, reconciliations, receipts, and audit logs — are subject to mandatory retention under applicable tax law. In the United States this is typically a minimum of seven (7) years; some categories and jurisdictions require longer. During the legally-required retention period, financial records cannot be permanently deleted on request, even if you exercise your deletion right under Section 13.3 or under applicable state privacy law. This retention rule is a legal-obligation carve-out and survives your Account closure for the period required by law. Account-level configuration data (such as your branding or preferences) is not subject to this carve-out and is deletable on request.
22.5 Export Right
You may export your complete bookkeeping data from the Accounting Feature at any time during your Account's active period, and for at least thirty (30) days after Account closure, in a portable machine-readable format (the "CPA Package"). The CPA Package satisfies in full any data-portability obligation we owe under applicable law for bookkeeping data.
22.6 Invited Accountant Access
You may invite specific persons (such as your accountant or bookkeeper) to access your books on a read-only basis. Each invitation creates a limited license for the invited party to view only your books. Every action by the invited party is automatically audit-logged. You may revoke the invitation at any time.
22.7 No Cross-User Visibility
Accounting Feature data is strictly siloed per Account by row-level security at the database. Another User on TheGuys.app — including Performers you have engaged or Dispatchers who have engaged you — cannot see your books, receipts, vendor names, financial reports, or any other Accounting Feature data.
22.8 No Secondary Use of Identifiable Books Data
We process your identifiable Accounting Feature data only to provide the Accounting Feature to you. We do not sell your identifiable books data, do not use it for advertising, do not use it as input to AI engagement recommendations or AI model training in identifiable form, and do not use it in identifiable form for any purpose unrelated to operating the feature, enforcing our agreements, and complying with law. We may create de-identified, aggregated data from Accounting Feature data under the safeguards and public commitments in Section 9.7; that data never identifies you, your business, or your books, and no third party ever receives your identifiable financial records.
23. Clients — Invoice Delivery and Payment Page Disclosures
23.1 Who This Section Is For
This Section 23 is written for Clients: the customers of a Dispatcher who receive an invoice from that Dispatcher through the Platform. If you received an email with an invoice and a payment link from a business that uses TheGuys.app, this Section describes what we collect from and about you, why, and what your choices are. You do not need an Account to receive, view, or pay an invoice, and nothing about invoice delivery or payment requires one. After you pay, your receipt may include one optional invitation, described in Section 23.9; whether to act on it is entirely your choice.
The invoice is the Dispatcher's invoice. The Dispatcher — the contractor or business you hired — chose what to bill, sent the invoice to you at the email address they hold for you, and is the party responsible to you for the work, the amounts, and any refund, credit, or dispute. TheGuys App provides the software that builds and delivers the invoice, hosts the invoice payment page, and — if you choose to pay online — collects your payment through Stripe on the Dispatcher's behalf and passes it on to the Dispatcher. Your card statement shows the Dispatcher's business name.
23.2 What We Collect From and About Clients
From the Dispatcher. The name, business name, email address, phone number, and billing address the Dispatcher entered for you on the invoice, together with the invoice itself (line items, prices, notes, invoice number, and dates). The Dispatcher may have entered your phone number and billing address when creating the job rather than when creating the invoice; either way we hold them for the Dispatcher and use them only as described in this Section 23. We do not call or send text messages to Clients.
When you open the invoice payment page. The payment link in your email opens a private page for that one invoice. When that page is requested we record, against the invoice: the date and time; a one-way hashed (encoded) form of the requesting IP address and of the browser or device identifier — never the raw values; whether the request looked like an automated link scanner rather than a person; whether the page was actually interacted with (a tap, click, key press, or scroll); whether the Pay button was pressed; and, for a payment attempt, a short outcome code (for example, "card declined" or "too many requests"). We do not record anything you type, and we do not use advertising or analytics cookies on the payment page. Separately, and only to prevent abuse, the raw IP address is held in a rate-limit counter that expires automatically within about one hour.
When you pay through the Platform. You enter your payment-card details directly into a payment form provided by Stripe. Your card number and security code go to Stripe and never pass through our servers; we do not receive or store your full card number, expiration date, or security code. From Stripe we receive and keep: that a payment was made, its amount and date, Stripe's identifiers for the payment, and the payment's outcome. We record the payment in a payment ledger with the invoice number, the email address the invoice was sent to, and the amount. If you later dispute the charge with your card issuer, Stripe notifies us and we record the dispute against the invoice.
When we email you. We use the email address the Dispatcher entered for you to deliver the invoice and, after you pay through the Platform, a paid receipt with a PAID copy of the invoice attached. Both are transactional messages about your invoice; we do not send Clients marketing email. The paid receipt may additionally carry the single optional invitation described in Section 23.9 — always below your payment information, and never changing the subject line. Replies to the invoice email go to the Dispatcher, not to us.
What we do NOT collect from Clients. We do not collect your precise location, your contacts, or any information from your device beyond the ordinary connection data described above. We do not require you to create an Account, and we do not build a profile of you across Dispatchers.
23.3 How We Use Client Information
- To deliver the Dispatcher's invoice to you and to show you the invoice on the payment page.
- To process your payment through Stripe if you choose to pay online, to send you the paid receipt, to record the payment, and to tell the Dispatcher the invoice was paid.
- To check, when preparing your paid receipt, whether the email address the invoice was sent to is already associated with an Account, solely to choose which of the two invitations described in Section 23.9 (if either) appears in that receipt. The result of this check is not shared with the Dispatcher and is not used for any other purpose.
- To pass the payment on to the Dispatcher, less the fees described in the Terms of Service, which are the Dispatcher's fees and are never added to your bill by us.
- To prevent fraud and abuse (rate limiting, scanner detection, Stripe's fraud tools) and to handle any payment dispute.
- To understand, in aggregate and for each Dispatcher, whether invoices sent through the Platform are being opened and paid, so that we can operate and improve the service. This is analytics only; it is never used to make any decision about you.
- To comply with law, enforce our agreements, and keep the financial records described in Section 11.
We do not sell Client information, do not share it for advertising, and do not use it to train any artificial-intelligence model in identifiable form.
23.4 Who Sees Client Information
- The Dispatcher — sees the invoice they sent you and its status: when it was emailed, the date it was first viewed, whether it has been paid, and the amount and date of payment. The Dispatcher does not see your card details.
- Stripe — processes your payment under Stripe's own privacy policy (https://stripe.com/privacy). Stripe receives your card details directly from you and may set cookies in its payment form for fraud prevention.
- Our service providers in Section 9.2 that host the Platform, send its email, limit abusive traffic, and monitor errors, on our behalf and under contract.
- Others only as described in Section 9.3 (legal and safety reasons) and Section 9.4 (a business transaction).
Performers (the Dispatcher's crew) never see your payment details.
23.5 Your Choices as a Client
- You do not have to pay online. The payment link is one way to pay; you may pay the Dispatcher any other way you and they arrange. If you pay outside the Platform, we receive nothing about that payment.
- You may leave the payment page at any time. Pressing Cancel on the payment page charges nothing and cancels nothing; the only record is the page-activity event described in Section 23.2 (that the page was opened and interacted with). The link continues to work until the invoice is paid, the Dispatcher cancels or replaces it, or the link expires.
- The invitation in your paid receipt is optional. Ignoring it changes nothing about your invoice, your payment, or your dealings with the Dispatcher, and we do not send follow-up or reminder emails about it. See Section 23.9.
- You may exercise the rights in Section 13. To do so, email legal@theguys.app with the subject line "Privacy Rights Request," the email address the invoice was sent to, and the invoice number, as described in Section 14. Because payment records are financial records, they are subject to the retention rule in Section 13.3 and cannot be deleted on request during the required retention period. Questions about the work, the amounts billed, refunds, or credits are for the Dispatcher — their contact details are on the invoice and on the payment page.
23.6 Retention of Client Information
Invoices, payment records, paid receipts, and payment page activity are retained for the periods stated in Section 11. Rate-limit counters expire automatically. When retention ends and no legal obligation applies, we delete the information or de-identify it.
23.7 The Dispatcher's Role
The Dispatcher who invoiced you decides what information to enter about you and is responsible, as a separate controller, for having a lawful basis to hold and use it and for honoring your requests about it (Section 19). We act on the Dispatcher's direction to deliver the invoice and, if you choose to pay online, to collect the payment.
23.8 Not for Children; U.S. Only
The invoice payment page is intended for adults in the United States who have hired a Dispatcher, consistent with Sections 16 and 17.
23.9 The Optional Invitation in Your Paid Receipt
When you pay an invoice through the Platform, the paid receipt described in Section 23.2 may include one short, clearly separated invitation. Which one you see depends on a single check we run when the receipt is prepared: whether the email address the invoice was sent to is already associated with an Account.
- If it is not, the receipt may invite you to create an Account of your own — for example, so you can post jobs and build a crew of your own on the Platform. The invitation is a link to the Platform's ordinary sign-up page.
- If it is, the receipt may instead note that the address is associated with an Account and offer to connect that Account with the Dispatcher who invoiced you — for example, by adding the Dispatcher to your crew. The link opens the Platform; after you sign in, you decide whether to send the Dispatcher that invitation through the Platform's normal invitation flow. Nothing is sent to the Dispatcher, and no connection between you is created, unless you choose to send it there.
The invitation is always optional and always secondary: it never changes the receipt's subject line, never appears above your payment information, and ignoring it changes nothing about your invoice, your payment, or your dealings with the Dispatcher. We do not send follow-up or reminder emails about it. The result of the account check is used only to choose which invitation appears in your own receipt; it is not shared with the Dispatcher, not used for advertising, and not used to build a profile of you.
If you choose to create an Account, you become a User: the Terms of Service and the User-facing sections of this Privacy Policy then govern what you do with that Account. Your invoice and payment records as a Client remain governed by this Section 23.
Last updated: August 31, 2026
© 2026 TheGuys App LLC. All rights reserved.
